Description=Process Core Dump
Documentation=man:systemd-coredump(8)
DefaultDependencies=no
-RequiresMountsFor=/var/lib/systemd/coredump
Conflicts=shutdown.target
After=systemd-remount-fs.service systemd-journald.socket
Requires=systemd-journald.socket
ExecStart=-@rootlibexecdir@/systemd-coredump
Nice=9
OOMScoreAdjust=500
+RuntimeMaxSec=5min
+PrivateTmp=yes
+PrivateDevices=yes
PrivateNetwork=yes
ProtectSystem=strict
-RuntimeMaxSec=5min
-SystemCallArchitectures=native
-ReadWritePaths=/var/lib/systemd/coredump
+ProtectHome=yes
+ProtectControlGroups=yes
+ProtectKernelTunables=yes
ProtectKernelModules=yes
+MemoryDenyWriteExecute=yes
+RestrictRealtime=yes
+RestrictNamespaces=yes
+RestrictAddressFamilies=AF_UNIX
+SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @reboot @swap
+SystemCallArchitectures=native
+LockPersonality=yes
+IPAddressDeny=any
+StateDirectory=systemd/coredump